CVE-2023-25802: Roxy-WI has Path Traversal vulnerability
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize dir/../filename sequences, such as /etc/nginx/../passwd, allowing an actor to gain information about a server. Version 6.3.6.0 has a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25802?
CVE-2023-25802 has been assigned a moderate severity level due to its potential to expose sensitive server information.
How do I fix CVE-2023-25802?
To fix CVE-2023-25802, upgrade Roxy-WI to version 6.3.6.0 or later, which includes a patch addressing this vulnerability.
What does CVE-2023-25802 exploit?
CVE-2023-25802 exploits improper handling of directory traversal sequences, allowing unauthorized access to server files.
Who is affected by CVE-2023-25802?
CVE-2023-25802 affects users of Roxy-WI versions prior to 6.3.6.0.
What systems are impacted by CVE-2023-25802?
CVE-2023-25802 impacts systems running web servers managed by Roxy-WI, including Haproxy, Nginx, and Apache.